H6.08.3export before account deletiondesignresearch

Offer data export before deletion

Aliases: download my data · backup before delete · portability gate

What it is

Deletion irreversibly takes away the copy of the person’s data that lives in the product. Export as a prerequisite means that before final confirm, a completable archive download (or a send to a verified mailbox) is offered, and the person either sees the archive ready or explicitly waives export. This entry is so confirm does not happen with no copy. It does not explain how long deletion takes—that is scope and timeline—and it does not handle statutory retention or data already in third-party hands.

Why it happens

People arrive at deletion under emotion or time pressure and will not first walk a separate “download my data” corner whose pack may take hours. If delete and export are unrelated settings items, the lived order is almost always delete first, remember the files later. A prerequisite inserts export on the critical path: either the pack is downloadable, or they check “I waive export.” Packing has generation delay; the prerequisite must handle “not ready yet”: do not make a submitted delete irreversible while the pack is still building, or at least delay delete until the pack is ready or they explicitly decline to wait. The format must open outside the product, or the prerequisite is theatre.

Studying it

Compare “delete and export as separate settings” with “the delete flow must pass through export or waiver,” looking at whether people still have their data after delete, and whether waiting for the pack causes them to abandon deletion.

Independent variables: export inserted before confirm, visible pack time, explicit waiver allowed, whether the format opens independently. Dependent variables: share who obtain a pack before delete, support after delete from having no backup, flow abandonments caused by export wait.

Labs can pack tiny accounts instantly; real large accounts must measure delay. Showing an export button is not a successful prerequisite—at confirm the pack must be downloadable or the waiver recorded. The download itself should re-authenticate; do not treat a long-open session as that check.

Where it stops holding

Data the person is not legally allowed to receive (reports about others, unfinished risk files) must stay out of the pack; the manifest should say what is missing so the prerequisite is not mistaken for “everything.” Empty accounts may skip export by default but still show “nothing to export.” When the export system is down, do not trap people outside deletion: allow “export unavailable, delete anyway” as an explicit choice with a record. For enterprise accounts the export audience may be an admin; a personal delete then becomes “ask your admin to export.”

Applying it

  • Before final confirm, offer “download my data” with pack status; keep confirm disabled until the pack is ready, unless they check waiver.
  • Send the pack to a verified mailbox or a download link after a fresh authentication; the format must open outside the product; list classes not included.
  • Waiver needs its own confirm line: “after deletion this data cannot be retrieved from this product.”
  • Verify: reaching confirm without waiver, the person can open a non-empty pack (or see “account empty”); confirm is blocked while the pack is not ready. Use an account with media and settings, and check the pack opens outside the product with the key classes in it. After deletion, in-product download must be impossible.

Related

  • Within the group: H6.08.1 Account deletion must not be deliberately hidden · H6.08.2 State what will be deleted and by when
  • Adjacent: H8.04 Copy, share, and export · H6.14 Account deletion and data erasure
  • Search terms: data portability · export before delete · download my data

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/H6.08.3